Avatar billede missus Nybegynder
20. december 2010 - 20:50 Der er 30 kommentarer og
1 løsning

Hjælp til log file

Hjælp til at rense pc:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:47:16, on 20-12-2010
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe
C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
C:\Program Files (x86)\SHARKOON Technologies GmbH\SHARKOON STATION\Majestic.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Spyware Doctor\pctsTray.exe
C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ekstrabladet.dk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
R3 - URLSearchHook: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\Spyware Doctor\BDT\PCTBrowserDefender.dll
O3 - Toolbar: ZoneAlarm Security Toolbar - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files (x86)\ZoneAlarm_Security\tbZone.dll
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SHARKOON STATION] C:\Program Files (x86)\SHARKOON Technologies GmbH\SHARKOON STATION\Majestic.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files (x86)\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Default user')
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files (x86)\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9022 bytes
Avatar billede johnstigers Seniormester
20. december 2010 - 20:59 #1
Hent og gem ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe  på dit skrivebord.

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::

Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.

Guide lånt af F-arn.
Avatar billede johnstigers Seniormester
20. december 2010 - 21:00 #2
Combofix log er jeg ikke så stærk i, så vent til rette person kommer forbi.
Avatar billede missus Nybegynder
20. december 2010 - 21:31 #3
ok
Avatar billede missus Nybegynder
20. december 2010 - 21:32 #4
combofix kommer her:

ComboFix 10-12-20.01 - Missus 20-12-2010  21:25:34.2.4 - x64
Microsoft Windows 7 Ultimate  6.1.7600.0.1252.45.1033.18.6007.4287 [GMT 1:00]
Kører fra: c:\users\Missus\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Missus\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
AV: ZoneAlarm Security Suite Antivirus *Disabled/Updated* {E9467272-859A-F159-FA9E-55E7E32D7A25}
FW: ZoneAlarm Security Suite Firewall *Disabled* {D17DF357-CFF5-F001-D1C1-FCD21DFE3D5E}
SP: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
SP: ZoneAlarm Security Suite Anti-Spyware *Disabled/Updated* {52279396-A3A0-FED7-C02E-6E9598AA3098}
.

(((((((((((((((((((((((((((((  Filer skabt fra 2010-11-20 til 2010-12-20  )))))))))))))))))))))))))))))))))))
.

2010-12-20 20:28 . 2010-12-20 20:28    --------    d-----w-    c:\users\Default\AppData\Local\temp
2010-12-20 19:45 . 2010-12-20 19:45    --------    d-----w-    c:\program files (x86)\Trend Micro
2010-12-20 19:27 . 2010-12-20 19:27    --------    d-----w-    c:\programdata\Kaspersky SDK
2010-12-20 19:19 . 2010-08-29 01:53    72704    ----a-w-    c:\windows\zllsputility.exe
2010-12-20 19:19 . 2009-10-12 17:15    157712    ----a-w-    c:\windows\system32\drivers\kl1.sys
2010-12-20 19:18 . 2010-12-20 19:18    --------    d-----w-    c:\windows\system32\ZoneLabs
2010-12-20 19:18 . 2010-06-09 18:16    456280    ----a-w-    c:\windows\SysWow64\drivers\vsdatant.sys
2010-12-20 19:05 . 2010-12-20 19:05    --------    d-----w-    c:\windows\system32\appmgmt
2010-12-20 18:53 . 2010-12-20 18:53    --------    d-----w-    c:\program files (x86)\ZoneAlarm_Security
2010-12-20 18:53 . 2010-12-20 18:53    --------    d-----w-    c:\program files\CheckPoint
2010-12-20 18:52 . 2010-04-09 11:06    374664    ----a-w-    c:\windows\system32\drivers\netio.sys
2010-12-20 18:52 . 2010-08-29 01:53    69120    ----a-w-    c:\windows\SysWow64\zlcomm.dll
2010-12-20 18:52 . 2010-08-29 01:53    103936    ----a-w-    c:\windows\SysWow64\zlcommdb.dll
2010-12-20 18:52 . 2010-12-20 19:37    --------    d-----w-    c:\windows\SysWow64\ZoneLabs
2010-12-20 18:52 . 2010-08-29 01:53    1238528    ----a-w-    c:\windows\SysWow64\zpeng25.dll
2010-12-20 18:52 . 2010-06-09 18:16    456280    ----a-w-    c:\windows\system32\drivers\vsdatant.sys
2010-12-20 18:52 . 2010-12-20 18:52    --------    d-----w-    c:\program files (x86)\Zone Labs
2010-12-20 16:53 . 2010-01-22 08:56    149456    ----a-w-    c:\windows\SGDetectionTool.dll
2010-12-20 16:53 . 2010-01-22 08:55    767952    ----a-w-    c:\windows\BDTSupport.dll
2010-12-20 16:53 . 2010-01-22 08:56    165840    ----a-w-    c:\windows\PCTBDRes.dll
2010-12-20 16:53 . 2010-01-22 08:56    1652688    ----a-w-    c:\windows\PCTBDCore.dll
2010-12-20 16:52 . 2010-02-05 08:18    133072    ----a-w-    c:\windows\system32\drivers\pctwfpfilter64.sys
2010-12-20 16:52 . 2010-02-05 08:17    306648    ----a-w-    c:\windows\system32\drivers\pctgntdi64.sys
2010-12-20 16:52 . 2010-03-29 09:06    233488    ----a-w-    c:\windows\system32\drivers\PCTCore64.sys
2010-12-20 16:51 . 2010-04-08 14:06    92896    ----a-w-    c:\windows\system32\drivers\pctplsg64.sys
2010-12-20 16:51 . 2010-12-20 20:08    --------    d-----w-    c:\program files (x86)\Spyware Doctor
2010-12-20 16:51 . 2010-12-20 16:53    --------    d-----w-    c:\program files (x86)\Common Files\PC Tools
2010-12-20 16:51 . 2010-12-20 16:51    --------    d-----w-    c:\programdata\PC Tools
2010-12-17 20:56 . 2010-12-17 20:56    --------    d-----w-    c:\programdata\CheckPoint
2010-12-17 20:25 . 2010-12-20 20:22    --------    d-----w-    c:\windows\Internet Logs
2010-12-15 17:48 . 2010-11-04 06:35    1194496    ----a-w-    c:\windows\system32\wininet.dll
2010-12-14 21:40 . 2010-12-14 21:40    --------    d-----w-    c:\program files (x86)\Conduit
2010-12-14 21:40 . 2010-12-20 19:39    --------    d-----w-    c:\program files (x86)\uTorrentBar
2010-12-14 21:40 . 2010-12-14 21:40    --------    d-----w-    C:\extensions
2010-12-13 20:39 . 2010-12-13 20:39    --------    d-----w-    c:\program files (x86)\Common Files\Java
2010-12-13 20:39 . 2010-12-13 20:39    472808    ----a-w-    c:\windows\SysWow64\deployJava1.dll
2010-12-13 20:39 . 2010-12-13 20:39    --------    d-----w-    c:\program files (x86)\Java
2010-12-12 12:01 . 2010-12-12 12:01    --------    d-----w-    c:\program files (x86)\Hewlett-Packard
2010-12-10 16:11 . 2010-12-10 16:11    --------    d-----w-    c:\program files (x86)\Common Files\Windows Live
2010-12-09 22:56 . 2010-12-09 22:56    --------    d-----w-    c:\users\Default\AppData\Local\Microsoft Help
2010-12-09 22:44 . 2010-12-09 22:44    --------    d-----w-    c:\windows\Sun
2010-12-09 22:44 . 2010-12-09 22:44    521448    ----a-w-    c:\windows\system32\deployJava1.dll
2010-12-09 22:44 . 2010-12-09 22:44    --------    d-----w-    c:\program files\Java
2010-12-09 22:42 . 2010-12-09 22:42    --------    d-----w-    c:\program files (x86)\Common Files\Adobe
2010-12-09 21:20 . 2010-12-09 21:20    --------    d-sh--w-    c:\programdata\DSS
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\windows\SysWow64\AGEIA
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\program files (x86)\AGEIA Technologies
2010-12-09 20:21 . 2010-12-20 18:39    --------    d-----w-    c:\program files (x86)\Common Files\Wise Installation Wizard
2010-12-09 20:20 . 2010-12-11 10:06    --------    d-----w-    C:\Spil
2010-12-09 20:18 . 2010-12-09 20:19    --------    d-----w-    c:\program files (x86)\DAEMON Tools Lite
2010-12-09 19:34 . 2004-08-04 14:52    6067    ----a-w-    c:\windows\SysWow64\drivers\SnxUF2.sys
2010-12-09 19:34 . 2010-12-09 19:34    --------    d--h--w-    c:\program files (x86)\InstallShield Installation Information
2010-12-09 19:34 . 2010-12-09 19:34    --------    d-----w-    c:\program files (x86)\SHARKOON Technologies GmbH
2010-12-09 19:34 . 2004-08-19 16:30    46280    ----a-w-    c:\windows\SysWow64\drivers\UALFDrv2.sys
2010-12-09 19:34 . 2010-12-09 19:34    --------    d-----w-    c:\program files (x86)\Common Files\InstallShield
2010-12-09 19:00 . 2010-12-09 19:00    --------    d-----w-    c:\windows\SysWow64\Wat
2010-12-09 19:00 . 2010-12-09 19:00    --------    d-----w-    c:\windows\system32\Wat
2010-12-09 18:46 . 2010-12-09 18:46    --------    d-----w-    c:\program files\ESET
2010-12-09 18:27 . 2010-12-09 18:27    --------    d-----w-    c:\program files (x86)\CCleaner
2010-12-09 18:08 . 2010-12-09 18:12    --------    d-----w-    c:\program files (x86)\Microsoft Works
2010-12-09 18:08 . 2010-12-09 18:08    --------    d-----w-    c:\windows\PCHEALTH
2010-12-09 18:07 . 2010-12-09 18:07    --------    d-----w-    C:\IDE
2010-12-09 18:07 . 2010-12-09 18:07    --------    d-----w-    c:\program files (x86)\Microsoft Visual Studio 8
2010-12-09 18:06 . 2010-12-15 20:40    --------    d-----w-    c:\programdata\Microsoft Help
2010-12-09 18:06 . 2010-12-09 18:06    --------    d-----r-    C:\MSOCache
2010-12-09 18:00 . 2010-12-09 18:00    --------    d-----w-    c:\programdata\NVIDIA
2010-12-09 17:51 . 2010-12-09 17:51    --------    d-----w-    c:\programdata\NVIDIA Corporation
2010-12-09 17:51 . 2010-12-09 17:51    --------    d-----w-    c:\program files\NVIDIA Corporation
2010-12-09 17:50 . 2010-12-09 17:50    --------    d-----w-    c:\windows\SysWow64\RTCOM
2010-12-09 17:50 . 2010-12-09 17:50    --------    d-----w-    c:\program files\Realtek
2010-12-09 17:48 . 2010-12-09 18:08    --------    d-----w-    c:\program files (x86)\Microsoft.NET
2010-12-09 17:45 . 2009-07-13 18:01    3584    ----a-w-    c:\windows\system32\Spool\prtprocs\x64\da-DK\LXKPTPRC.DLL.mui
2010-12-09 17:45 . 2009-10-10 03:17    14336    ----a-w-    c:\windows\system32\drivers\sffp_sd.sys
2010-12-09 17:44 . 2010-03-04 04:32    243712    ----a-w-    c:\windows\system32\drivers\ks.sys
2010-12-09 17:43 . 2010-08-04 07:07    961024    ----a-w-    c:\windows\system32\CPFilters.dll
2010-12-09 17:43 . 2010-08-04 07:07    552960    ----a-w-    c:\windows\system32\msdri.dll
2010-12-09 17:43 . 2010-08-04 07:05    288256    ----a-w-    c:\windows\system32\MSNP.ax
2010-12-09 17:43 . 2010-08-04 07:05    258560    ----a-w-    c:\windows\system32\mpg2splt.ax
2010-12-09 17:43 . 2010-08-04 06:18    641536    ----a-w-    c:\windows\SysWow64\CPFilters.dll
2010-12-09 17:43 . 2010-08-04 06:15    204288    ----a-w-    c:\windows\SysWow64\MSNP.ax
2010-12-09 17:43 . 2010-08-04 06:15    199680    ----a-w-    c:\windows\SysWow64\mpg2splt.ax
2010-12-09 17:43 . 2009-12-13 09:46    613888    ----a-w-    c:\windows\system32\psisdecd.dll
2010-12-09 17:43 . 2009-12-13 09:30    465408    ----a-w-    c:\windows\SysWow64\psisdecd.dll
2010-12-09 17:43 . 2010-04-07 07:37    861184    ----a-w-    c:\windows\system32\oleaut32.dll
2010-12-09 17:43 . 2010-04-07 07:10    571904    ----a-w-    c:\windows\SysWow64\oleaut32.dll
2010-12-09 17:31 . 2009-11-25 11:47    99176    ----a-w-    c:\windows\SysWow64\PresentationHostProxy.dll
2010-12-09 17:31 . 2009-11-25 11:47    49472    ----a-w-    c:\windows\SysWow64\netfxperf.dll
2010-12-09 17:31 . 2009-11-25 11:47    48960    ----a-w-    c:\windows\system32\netfxperf.dll
2010-12-09 17:31 . 2009-11-25 11:47    297808    ----a-w-    c:\windows\SysWow64\mscoree.dll
2010-12-09 17:31 . 2009-11-25 11:47    295264    ----a-w-    c:\windows\SysWow64\PresentationHost.exe
2010-12-09 17:31 . 2009-11-25 11:47    1130824    ----a-w-    c:\windows\SysWow64\dfshim.dll
2010-12-09 17:31 . 2009-11-25 11:47    109912    ----a-w-    c:\windows\system32\PresentationHostProxy.dll
2010-12-09 17:31 . 2009-11-25 11:47    444752    ----a-w-    c:\windows\system32\mscoree.dll
2010-12-09 17:31 . 2009-11-25 11:47    320352    ----a-w-    c:\windows\system32\PresentationHost.exe
2010-12-09 17:31 . 2009-11-25 11:47    1942856    ----a-w-    c:\windows\system32\dfshim.dll
2010-12-09 17:30 . 2010-02-23 08:16    294912    ----a-w-    c:\windows\system32\browserchoice.exe
2010-12-09 17:26 . 2010-06-08 06:02    1233920    ----a-w-    c:\windows\SysWow64\msxml3.dll
2010-12-09 17:26 . 2010-06-08 05:36    1877504    ----a-w-    c:\windows\system32\msxml3.dll
2010-12-09 17:26 . 2010-05-19 19:48    144384    ----a-w-    c:\windows\system32\cdd.dll
2010-12-09 17:26 . 2010-08-26 05:27    148992    ----a-w-    c:\windows\system32\t2embed.dll
2010-12-09 17:26 . 2010-08-26 04:39    109056    ----a-w-    c:\windows\SysWow64\t2embed.dll
2010-12-09 17:26 . 2010-05-05 07:37    483840    ----a-w-    c:\windows\system32\StructuredQuery.dll
2010-12-09 17:26 . 2010-05-05 06:46    363520    ----a-w-    c:\windows\SysWow64\StructuredQuery.dll
2010-12-09 17:26 . 2010-08-21 06:38    1024512    ----a-w-    c:\windows\system32\wmpmde.dll
2010-12-09 17:26 . 2010-08-21 05:36    738816    ----a-w-    c:\windows\SysWow64\wmpmde.dll
2010-12-09 17:26 . 2009-10-19 14:46    100864    ----a-w-    c:\windows\system32\fontsub.dll
2010-12-09 17:26 . 2009-10-19 14:10    70656    ----a-w-    c:\windows\SysWow64\fontsub.dll
2010-12-09 17:21 . 2010-12-09 17:21    --------    d-----w-    c:\windows\SysWow64\Macromed
2010-12-09 17:19 . 2010-12-09 17:19    --------    d-sh--w-    c:\windows\SysWow64\%APPDATA%
2010-12-09 17:19 . 2010-12-20 19:39    --------    d-----w-    c:\program files (x86)\DAEMON Tools Toolbar
2010-12-09 17:18 . 2010-12-09 17:18    834544    ----a-w-    c:\windows\system32\drivers\sptd.sys
2010-12-09 17:18 . 2010-12-09 17:18    --------    d-----w-    c:\programdata\DAEMON Tools Lite
2010-12-09 17:18 . 2010-12-09 17:18    --------    d-----w-    c:\program files (x86)\Windows Live
2010-12-09 17:17 . 2010-12-09 17:17    --------    d-----w-    c:\program files\7-Zip
2010-12-09 17:17 . 2010-12-20 19:45    --------    d-sh--w-    c:\windows\Installer
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\program files (x86)\VideoLAN
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\custom matrices
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\C2MP
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\QuickTime
2010-12-09 17:15 . 2010-12-09 17:15    --------    d-----w-    c:\program files (x86)\Combined Community Codec Pack
2010-12-09 17:15 . 2010-12-09 17:15    --------    d-----w-    c:\program files (x86)\IObit

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-09 19:00 . 2009-12-18 17:16    419840    ----a-w-    c:\windows\system32\systemcpl.dll
2010-12-09 19:00 . 2009-07-13 23:52    14848    ----a-w-    c:\windows\system32\slwga.dll
2010-12-09 19:00 . 2009-07-13 23:36    13824    ----a-w-    c:\windows\SysWow64\slwga.dll
2010-12-09 19:00 . 2009-07-13 23:38    1008640    ----a-w-    c:\windows\system32\user32.dll
2010-12-09 19:00 . 2009-07-13 23:24    833024    ----a-w-    c:\windows\SysWow64\user32.dll
.

------- Sigcheck -------

  • 2010-12-09 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] . . c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] . . c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] . . c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
  • 2010-12-09 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] . . c:\windows\system32\user32.dll

  • 2010-12-09 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] . . c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] . . c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] . . c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
  • 2010-12-09 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] . . c:\windows\system32\user32.dll
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files (x86)\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]

[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-11-29 14:26    3908192    ----a-w-    c:\program files (x86)\ConduitEngine\ConduitEngine.dll

[HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]
2010-12-01 10:27    2735200    ----a-w-    c:\program files (x86)\ZoneAlarm_Security\tbZone.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-11-29 3908192]
"{91da5e8a-3318-4f8c-b67e-5964de3ab546}"= "c:\program files (x86)\ZoneAlarm_Security\tbZone.dll" [2010-12-01 2735200]

[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]

[HKEY_CLASSES_ROOT\clsid\{91da5e8a-3318-4f8c-b67e-5964de3ab546}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SHARKOON STATION"="c:\program files (x86)\SHARKOON Technologies GmbH\SHARKOON STATION\Majestic.exe" [2004-11-11 327680]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"ZoneAlarm Client"="c:\program files (x86)\Zone Labs\ZoneAlarm\zlclient.exe" [2010-08-29 1039360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files (x86)\Spyware Doctor\pctsAuxs.exe [2010-03-11 366840]
R3 UALFDrv2;UALFDrv2;c:\windows\system32\DRIVERS\UALFDrv2.sys [x]
R3 WatAdminSvc;WatAdminSvc; [x]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore64.sys [2010-03-29 233488]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-09 834544]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files (x86)\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-22 112592]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2009-11-16 123200]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]


--- Andre Services/Drivers i Hukommelsen ---

*Deregistered* - PCTSDInjDriver64
.

--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-12-09 2715704]
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://ekstrabladet.dk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&ksporter til Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
.
- - - - TOMME GENVEJE FJERNET - - - -

WebBrowser-{91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - (no file)


.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{57B012C9-5EAD-441B-9925-6B560B543D87}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.0.474.0"
"UniqueId"="001E420F4D012425"
"ScannerBuild"=dword:000017cd
"ScannerVersionId"=dword:00001214
"ScannerVersion"="Open window for status."
"FixId"=dword:00000007

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Gennemført tid: 2010-12-20  21:29:59
ComboFix-quarantined-files.txt  2010-12-20 20:29
ComboFix2.txt  2010-12-20 20:15

Pre-Kørsel: 927.352.958.976 byte ledig
Post-Kørsel: 927.303.520.256 byte ledig

- - End Of File - - 0318996299D11171556BB0D5F0D1E047
Avatar billede missus Nybegynder
20. december 2010 - 21:49 #5
Foreløbig tak for hjælpen -> john_stigers
Avatar billede missus Nybegynder
20. december 2010 - 22:46 #6
Anyone ?
20. december 2010 - 22:46 #7
Jeg er ikke 'rette' person; men oplever du problemer ?
Avatar billede missus Nybegynder
20. december 2010 - 22:48 #8
ja - min nod 32 melder  Win32/Olmarik
20. december 2010 - 22:49 #9
Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/manual-for-installation-og-brug-af-ccleaner/
http://vistaguide.dk/?Artikler/CCleaner-GuideTilOptimeringAfVista/763
Lad programmet foretage en oprydning...

--------

Hent Malwarebytes Anti-Malware herfra:
http://www.besttechie.net/tools/mbam-setup.exe

Installer programmet - når det er gjort skal du lade programmet opdatere sig. Herefter åbner et vindue, hvor du skal flytte prikken til "Kør et fuldstændigt systemscan" - klik på Skan Knappen - lad programmet arbejde. Når det er færdig (det tager lidt tid afhængig af hvor meget du har på computeren).
Derefter - Tryk på "Vis resultater" knappen efter scanningen - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen.
Kopier indhold af log herind ...
Avatar billede missus Nybegynder
20. december 2010 - 23:19 #10
ok - er i gang
Avatar billede missus Nybegynder
20. december 2010 - 23:28 #11
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 5363

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

20-12-2010 23:28:23
mbam-log-2010-12-20 (23-28-23).txt

Skanningstype: Fuldstændig skanning (C:\|D:\|E:\|F:\|)
Objekter skannet: 302830
Tid gået: 18 minut(ter), 50 sekund(er)

Hukommelses Processorer Inficeret: 0
Hukommelses Moduler Inficeret: 0
Registreringsdatabasenøgler Inficeret: 0
Registreringsdatabaseværdier Inficeret: 0
Registreringsdatabasedata Objekter Inficeret: 0
Inficerede Mapper: 0
Inficerede Filer: 3

Hukommelses Processorer Inficeret:
(Ingen skadelige objekter blev fundet)

Hukommelses Moduler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasenøgler Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabaseværdier Inficeret:
(Ingen skadelige objekter blev fundet)

Registreringsdatabasedata Objekter Inficeret:
(Ingen skadelige objekter blev fundet)

Inficerede Mapper:
(Ingen skadelige objekter blev fundet)

Inficerede Filer:
c:\Users\Missus\Desktop\removewat.exe (HackTool.Wpakill) -> Quarantined and deleted successfully.
f:\programmer\Ny mappe\youtube.google.video.grabber.v1.0.0.0.retail-explosion\Setup.exe (Rogue.BulletProofSpyware) -> Quarantined and deleted successfully.
f:\Spil\call of duty 4\call_of_duty_4_crackfix_and_keygen-razor1911\rzr-cod4.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
20. december 2010 - 23:37 #12
Nåååå - så du 'leger' med crackfix_and_keygen ... så er du jo næsten selv ude om det !!!

(Kan ikke nå mere nu.. Andre i denne tråd ?)
Avatar billede missus Nybegynder
20. december 2010 - 23:42 #13
ok - tak for hjælpen
Avatar billede f-arn Guru
21. december 2010 - 12:26 #14
Har du en Windows CD ?
Jeg kan se der er vrøvl med nogle Windows filer.
Avatar billede missus Nybegynder
21. december 2010 - 20:10 #15
Nej det har jeg ikke
Avatar billede missus Nybegynder
21. december 2010 - 21:03 #16
Anyone ?

MBR sector of the 1. physical disk - Win32/Olmarik.AJL trojan - action selection postponed until scan completion
Avatar billede f-arn Guru
22. december 2010 - 09:44 #17
Download Tdsskiller.zip på dit skrivebord og pak den ud i en mappe.

Kør TDSSKiller.exe -> Klik på "Start Scan"

Hvis en inficeret fil bliver fundet, vil "Default action" være Cure , klik på Continue
Hvis en mistænkelig fil opdages, vil "Default action" være Skip, klik på Continue

Genstart hvis den kræver det.

Hvis den genstarter kan du finde logfilen her :
C:\TDSSKiller.[Version]_[Dato]_[Tidspunkt]_log.txt.

Kopier den tekst herind I denne tråd.
Avatar billede missus Nybegynder
22. december 2010 - 18:51 #18
Hej f-arn

her kommer loggen ....



2010/12/22 18:32:53.0720    TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46
2010/12/22 18:32:53.0720    ================================================================================
2010/12/22 18:32:53.0720    SystemInfo:
2010/12/22 18:32:53.0720   
2010/12/22 18:32:53.0720    OS Version: 6.1.7600 ServicePack: 0.0
2010/12/22 18:32:53.0720    Product type: Workstation
2010/12/22 18:32:53.0720    ComputerName: MISSUS-PC
2010/12/22 18:32:53.0720    UserName: Missus
2010/12/22 18:32:53.0720    Windows directory: C:\Windows
2010/12/22 18:32:53.0720    System windows directory: C:\Windows
2010/12/22 18:32:53.0720    Running under WOW64
2010/12/22 18:32:53.0720    Processor architecture: Intel x64
2010/12/22 18:32:53.0720    Number of processors: 4
2010/12/22 18:32:53.0720    Page size: 0x1000
2010/12/22 18:32:53.0720    Boot type: Normal boot
2010/12/22 18:32:53.0720    ================================================================================
2010/12/22 18:32:53.0720    Utility is running under WOW64
2010/12/22 18:32:56.0419    Initialize success
2010/12/22 18:33:01.0130    ================================================================================
2010/12/22 18:33:01.0130    Scan started
2010/12/22 18:33:01.0130    Mode: Manual;
2010/12/22 18:33:01.0130    ================================================================================
2010/12/22 18:33:02.0488    1394ohci        (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
2010/12/22 18:33:02.0519    ACPI            (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
2010/12/22 18:33:02.0550    AcpiPmi        (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
2010/12/22 18:33:02.0581    adp94xx        (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
2010/12/22 18:33:02.0597    adpahci        (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
2010/12/22 18:33:02.0628    adpu320        (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
2010/12/22 18:33:02.0659    AFD            (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
2010/12/22 18:33:02.0675    agp440          (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
2010/12/22 18:33:02.0706    aliide          (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
2010/12/22 18:33:02.0722    amdide          (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
2010/12/22 18:33:02.0737    AmdK8          (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
2010/12/22 18:33:02.0753    AmdPPM          (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
2010/12/22 18:33:02.0784    amdsata        (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
2010/12/22 18:33:02.0800    amdsbs          (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
2010/12/22 18:33:02.0815    amdxata        (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
2010/12/22 18:33:02.0846    AppID          (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
2010/12/22 18:33:02.0862    arc            (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
2010/12/22 18:33:02.0878    arcsas          (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
2010/12/22 18:33:02.0893    AsyncMac        (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
2010/12/22 18:33:02.0924    atapi          (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
2010/12/22 18:33:02.0956    b06bdrv        (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
2010/12/22 18:33:02.0987    b57nd60a        (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
2010/12/22 18:33:03.0018    Beep            (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
2010/12/22 18:33:03.0034    blbdrive        (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
2010/12/22 18:33:03.0065    bowser          (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys
2010/12/22 18:33:03.0080    BrFiltLo        (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
2010/12/22 18:33:03.0096    BrFiltUp        (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
2010/12/22 18:33:03.0112    Brserid        (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
2010/12/22 18:33:03.0143    BrSerWdm        (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
2010/12/22 18:33:03.0158    BrUsbMdm        (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
2010/12/22 18:33:03.0174    BrUsbSer        (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
2010/12/22 18:33:03.0190    BTHMODEM        (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
2010/12/22 18:33:03.0236    cdfs            (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
2010/12/22 18:33:03.0268    cdrom          (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
2010/12/22 18:33:03.0299    circlass        (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
2010/12/22 18:33:03.0330    CLFS            (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
2010/12/22 18:33:03.0377    CmBatt          (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
2010/12/22 18:33:03.0424    cmdide          (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
2010/12/22 18:33:03.0455    CNG            (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
2010/12/22 18:33:03.0486    Compbatt        (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
2010/12/22 18:33:03.0502    CompositeBus    (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
2010/12/22 18:33:03.0533    crcdisk        (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
2010/12/22 18:33:03.0548    CSC            (4a6173c2279b498cd8f57cae504564cb) C:\Windows\system32\drivers\csc.sys
2010/12/22 18:33:03.0580    DfsC            (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
2010/12/22 18:33:03.0626    discache        (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
2010/12/22 18:33:03.0673    Disk            (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
2010/12/22 18:33:03.0736    drmkaud        (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
2010/12/22 18:33:03.0767    DXGKrnl        (ebce0b0924835f635f620d19f0529dce) C:\Windows\System32\drivers\dxgkrnl.sys
2010/12/22 18:33:03.0782    E1G60          (edc6e9c057c9d7f83eea22b4cef5dcad) C:\Windows\system32\DRIVERS\E1G6032E.sys
2010/12/22 18:33:03.0829    eamon          (85e3ed13ec107a20d9b018328e0c9737) C:\Windows\system32\DRIVERS\eamon.sys
2010/12/22 18:33:03.0907    ebdrv          (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
2010/12/22 18:33:03.0985    ehdrv          (518fb66d5e21b2c246f96c1d9153cadc) C:\Windows\system32\DRIVERS\ehdrv.sys
2010/12/22 18:33:04.0016    elxstor        (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
2010/12/22 18:33:04.0048    epfwwfpr        (60643217107fd0dd2d11d0936f86506f) C:\Windows\system32\DRIVERS\epfwwfpr.sys
2010/12/22 18:33:04.0079    ErrDev          (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
2010/12/22 18:33:04.0110    exfat          (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
2010/12/22 18:33:04.0126    fastfat        (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
2010/12/22 18:33:04.0157    fdc            (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
2010/12/22 18:33:04.0188    FileInfo        (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
2010/12/22 18:33:04.0204    Filetrace      (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
2010/12/22 18:33:04.0219    flpydisk        (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
2010/12/22 18:33:04.0235    FltMgr          (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
2010/12/22 18:33:04.0266    FsDepends      (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
2010/12/22 18:33:04.0282    Fs_Rec          (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
2010/12/22 18:33:04.0313    gagp30kx        (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
2010/12/22 18:33:04.0328    hcw85cir        (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
2010/12/22 18:33:04.0344    HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
2010/12/22 18:33:04.0375    HDAudBus        (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
2010/12/22 18:33:04.0406    HidBatt        (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
2010/12/22 18:33:04.0422    HidBth          (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
2010/12/22 18:33:04.0438    HidIr          (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
2010/12/22 18:33:04.0469    HidUsb          (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
2010/12/22 18:33:04.0531    HpSAMD          (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
2010/12/22 18:33:04.0562    HTTP            (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
2010/12/22 18:33:04.0594    hwpolicy        (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
2010/12/22 18:33:04.0609    i8042prt        (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
2010/12/22 18:33:04.0625    iaStorV        (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
2010/12/22 18:33:04.0656    iirsp          (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
2010/12/22 18:33:04.0765    IntcAzAudAddService (3c4b4ee54febb09f7e9f58776de96dca) C:\Windows\system32\drivers\RTKVHD64.sys
2010/12/22 18:33:04.0796    intelide        (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
2010/12/22 18:33:04.0812    intelppm        (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
2010/12/22 18:33:04.0828    IpFilterDriver  (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2010/12/22 18:33:04.0859    IPMIDRV        (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
2010/12/22 18:33:04.0874    IPNAT          (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
2010/12/22 18:33:04.0890    IRENUM          (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
2010/12/22 18:33:04.0906    isapnp          (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
2010/12/22 18:33:04.0937    iScsiPrt        (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
2010/12/22 18:33:04.0968    kbdclass        (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
2010/12/22 18:33:04.0999    kbdhid          (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
2010/12/22 18:33:05.0015    KSecDD          (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
2010/12/22 18:33:05.0046    KSecPkg        (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
2010/12/22 18:33:05.0077    ksthunk        (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
2010/12/22 18:33:05.0108    lltdio          (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
2010/12/22 18:33:05.0140    LSI_FC          (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
2010/12/22 18:33:05.0140    LSI_SAS        (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
2010/12/22 18:33:05.0171    LSI_SAS2        (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
2010/12/22 18:33:05.0171    LSI_SCSI        (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
2010/12/22 18:33:05.0202    luafv          (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
2010/12/22 18:33:05.0233    megasas        (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
2010/12/22 18:33:05.0249    MegaSR          (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
2010/12/22 18:33:05.0296    Modem          (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
2010/12/22 18:33:05.0311    monitor        (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
2010/12/22 18:33:05.0342    mouclass        (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
2010/12/22 18:33:05.0374    mouhid          (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
2010/12/22 18:33:05.0389    mountmgr        (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
2010/12/22 18:33:05.0405    mpio            (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
2010/12/22 18:33:05.0420    mpsdrv          (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
2010/12/22 18:33:05.0452    MRxDAV          (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
2010/12/22 18:33:05.0483    mrxsmb          (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys
2010/12/22 18:33:05.0514    mrxsmb10        (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2010/12/22 18:33:05.0530    mrxsmb20        (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2010/12/22 18:33:05.0561    msahci          (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
2010/12/22 18:33:05.0576    msdsm          (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
2010/12/22 18:33:05.0608    Msfs            (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
2010/12/22 18:33:05.0623    mshidkmdf      (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
2010/12/22 18:33:05.0639    msisadrv        (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
2010/12/22 18:33:05.0701    MSKSSRV        (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
2010/12/22 18:33:05.0717    MSPCLOCK        (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
2010/12/22 18:33:05.0732    MSPQM          (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
2010/12/22 18:33:05.0764    MsRPC          (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
2010/12/22 18:33:05.0779    mssmbios        (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
2010/12/22 18:33:05.0795    MSTEE          (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
2010/12/22 18:33:05.0810    MTConfig        (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
2010/12/22 18:33:05.0826    Mup            (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
2010/12/22 18:33:05.0857    NativeWifiP    (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
2010/12/22 18:33:05.0888    NDIS            (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
2010/12/22 18:33:05.0920    NdisCap        (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
2010/12/22 18:33:05.0951    NdisTapi        (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
2010/12/22 18:33:05.0966    Ndisuio        (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
2010/12/22 18:33:05.0982    NdisWan        (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
2010/12/22 18:33:05.0998    NDProxy        (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
2010/12/22 18:33:06.0013    NetBIOS        (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
2010/12/22 18:33:06.0029    NetBT          (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
2010/12/22 18:33:06.0076    nfrd960        (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
2010/12/22 18:33:06.0107    Npfs            (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
2010/12/22 18:33:06.0122    nsiproxy        (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
2010/12/22 18:33:06.0154    Ntfs            (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
2010/12/22 18:33:06.0216    Null            (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
2010/12/22 18:33:06.0434    nvlddmkm        (f0fbfe1e29ff233b0e000054c1fb968a) C:\Windows\system32\DRIVERS\nvlddmkm.sys
2010/12/22 18:33:06.0481    nvraid          (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
2010/12/22 18:33:06.0497    nvstor          (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
2010/12/22 18:33:06.0528    nv_agp          (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
2010/12/22 18:33:06.0544    ohci1394        (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
2010/12/22 18:33:06.0559    Parport        (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
2010/12/22 18:33:06.0575    partmgr        (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
2010/12/22 18:33:06.0590    pci            (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
2010/12/22 18:33:06.0606    pciide          (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
2010/12/22 18:33:06.0637    pcmcia          (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
2010/12/22 18:33:06.0653    pcw            (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
2010/12/22 18:33:06.0668    PEAUTH          (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
2010/12/22 18:33:06.0746    PptpMiniport    (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
2010/12/22 18:33:06.0762    Processor      (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
2010/12/22 18:33:06.0793    Psched          (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
2010/12/22 18:33:06.0824    ql2300          (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
2010/12/22 18:33:06.0856    ql40xx          (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
2010/12/22 18:33:06.0902    QWAVEdrv        (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
2010/12/22 18:33:06.0918    RasAcd          (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
2010/12/22 18:33:06.0965    RasAgileVpn    (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
2010/12/22 18:33:06.0980    Rasl2tp        (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
2010/12/22 18:33:07.0027    RasPppoe        (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
2010/12/22 18:33:07.0043    RasSstp        (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
2010/12/22 18:33:07.0058    rdbss          (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
2010/12/22 18:33:07.0105    rdpbus          (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
2010/12/22 18:33:07.0136    RDPCDD          (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
2010/12/22 18:33:07.0168    RDPDR          (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\Windows\system32\drivers\rdpdr.sys
2010/12/22 18:33:07.0183    RDPENCDD        (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
2010/12/22 18:33:07.0214    RDPREFMP        (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
2010/12/22 18:33:07.0230    RDPWD          (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
2010/12/22 18:33:07.0246    rdyboost        (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
2010/12/22 18:33:07.0277    rspndr          (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
2010/12/22 18:33:07.0324    RTL8167        (abcb5a38a0d85bdf69b7877e1ad1eed5) C:\Windows\system32\DRIVERS\Rt64win7.sys
2010/12/22 18:33:07.0355    s3cap          (88af6e02ab19df7fd07ecdf9c91e9af6) C:\Windows\system32\DRIVERS\vms3cap.sys
2010/12/22 18:33:07.0402    sbp2port        (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
2010/12/22 18:33:07.0417    scfilter        (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
2010/12/22 18:33:07.0464    secdrv          (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
2010/12/22 18:33:07.0480    Serenum        (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
2010/12/22 18:33:07.0495    Serial          (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
2010/12/22 18:33:07.0511    sermouse        (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
2010/12/22 18:33:07.0558    sffdisk        (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
2010/12/22 18:33:07.0589    sffp_mmc        (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
2010/12/22 18:33:07.0589    sffp_sd        (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
2010/12/22 18:33:07.0620    sfloppy        (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
2010/12/22 18:33:07.0651    SiSRaid2        (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
2010/12/22 18:33:07.0667    SiSRaid4        (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
2010/12/22 18:33:07.0682    Smb            (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
2010/12/22 18:33:07.0714    spldr          (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
2010/12/22 18:33:07.0792    sptd            (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
2010/12/22 18:33:07.0792    Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
2010/12/22 18:33:07.0792    sptd - detected Locked file (1)
2010/12/22 18:33:07.0823    srv            (de6f5658da951c4bc8e498570b5b0d5f) C:\Windows\system32\DRIVERS\srv.sys
2010/12/22 18:33:07.0838    srv2            (4d33d59c0b930c523d29f9bd40cda9d2) C:\Windows\system32\DRIVERS\srv2.sys
2010/12/22 18:33:07.0870    srvnet          (5a663fd67049267bc5c3f3279e631ffb) C:\Windows\system32\DRIVERS\srvnet.sys
2010/12/22 18:33:07.0901    stexstor        (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
2010/12/22 18:33:07.0932    storflt        (ffd7a6f15b14234b5b0e5d49e7961895) C:\Windows\system32\DRIVERS\vmstorfl.sys
2010/12/22 18:33:07.0948    storvsc        (8fccbefc5c440b3c23454656e551b09a) C:\Windows\system32\DRIVERS\storvsc.sys
2010/12/22 18:33:07.0963    swenum          (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
2010/12/22 18:33:08.0026    Tcpip          (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
2010/12/22 18:33:08.0135    TCPIP6          (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
2010/12/22 18:33:08.0182    tcpipreg        (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
2010/12/22 18:33:08.0213    TDPIPE          (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
2010/12/22 18:33:08.0228    TDTCP          (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
2010/12/22 18:33:08.0244    tdx            (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
2010/12/22 18:33:08.0260    TermDD          (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
2010/12/22 18:33:08.0306    tssecsrv        (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
2010/12/22 18:33:08.0322    tunnel          (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
2010/12/22 18:33:08.0353    uagp35          (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
2010/12/22 18:33:08.0416    udfs            (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
2010/12/22 18:33:08.0431    uliagpkx        (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
2010/12/22 18:33:08.0462    umbus          (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
2010/12/22 18:33:08.0478    UmPass          (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
2010/12/22 18:33:08.0525    usbaudio        (77b01bc848298223a95d4ec23e1785a1) C:\Windows\system32\drivers\usbaudio.sys
2010/12/22 18:33:08.0540    usbccgp        (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
2010/12/22 18:33:08.0572    usbcir          (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
2010/12/22 18:33:08.0587    usbehci        (2ea4aff7be7eb4632e3aa8595b0803b5) C:\Windows\system32\DRIVERS\usbehci.sys
2010/12/22 18:33:08.0603    usbhub          (4c9042b8df86c1e8e6240c218b99b39b) C:\Windows\system32\DRIVERS\usbhub.sys
2010/12/22 18:33:08.0634    usbohci        (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
2010/12/22 18:33:08.0665    usbprint        (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
2010/12/22 18:33:08.0681    USBSTOR        (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2010/12/22 18:33:08.0696    usbuhci        (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
2010/12/22 18:33:08.0728    vdrvroot        (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
2010/12/22 18:33:08.0759    vga            (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
2010/12/22 18:33:08.0774    VgaSave        (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
2010/12/22 18:33:08.0806    vhdmp          (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
2010/12/22 18:33:08.0821    viaide          (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
2010/12/22 18:33:08.0837    vmbus          (1501699d7eda984abc4155a7da5738d1) C:\Windows\system32\DRIVERS\vmbus.sys
2010/12/22 18:33:08.0852    VMBusHID        (ae10c35761889e65a6f7176937c5592c) C:\Windows\system32\DRIVERS\VMBusHID.sys
2010/12/22 18:33:08.0884    volmgr          (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
2010/12/22 18:33:08.0899    volmgrx        (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
2010/12/22 18:33:08.0946    volsnap        (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
2010/12/22 18:33:08.0962    vsmraid        (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
2010/12/22 18:33:08.0993    vwifibus        (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
2010/12/22 18:33:09.0024    WacomPen        (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
2010/12/22 18:33:09.0040    WANARP          (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2010/12/22 18:33:09.0040    Wanarpv6        (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
2010/12/22 18:33:09.0086    Wd              (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
2010/12/22 18:33:09.0118    Wdf01000        (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
2010/12/22 18:33:09.0149    WfpLwf          (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
2010/12/22 18:33:09.0180    WIMMount        (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
2010/12/22 18:33:09.0242    WmiAcpi        (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
2010/12/22 18:33:09.0305    ws2ifsl        (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
2010/12/22 18:33:09.0320    WudfPf          (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
2010/12/22 18:33:09.0352    WUDFRd          (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
2010/12/22 18:33:09.0367    \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0)
2010/12/22 18:33:09.0398    ================================================================================
2010/12/22 18:33:09.0398    Scan finished
2010/12/22 18:33:09.0398    ================================================================================
2010/12/22 18:33:09.0414    Detected object count: 2
2010/12/22 18:33:37.0026    Locked file(sptd) - User select action: Skip
2010/12/22 18:33:37.0057    \HardDisk0 - will be cured after reboot
2010/12/22 18:33:37.0057    Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure
2010/12/22 18:33:42.0034    Deinitialize success

Jeg er kommet i tanke om at jeg eftermonterede en "gammel" harddisk som umiddelbart ikke havde virus, men da jeg pillede den fra, fik jeg ingen "alerts", så det må være den "gamle" harddisk som er blevet "curet"
Avatar billede f-arn Guru
22. december 2010 - 19:31 #19
den "gamle" harddisk som er blevet "curet"

\HardDisk0 er din Bootdisk, så det virker ikke sådan.

------

Slet den ComboFix du har og hent en ny.

Hent og gem ComboFix på dit skrivebord.

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil: combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede missus Nybegynder
22. december 2010 - 19:54 #20
Hej, log kommer her:

ComboFix 10-12-21.05 - Missus 22-12-2010  19:49:49.2.4 - x64
Microsoft Windows 7 Ultimate  6.1.7600.0.1252.45.1033.18.6007.4602 [GMT 1:00]
Kører fra: c:\users\Missus\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Missus\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
.

(((((((((((((((((((((((((((((  Filer skabt fra 2010-11-22 til 2010-12-22  )))))))))))))))))))))))))))))))))))
.

2010-12-22 18:51 . 2010-12-22 18:51    --------    d-----w-    c:\users\Default\AppData\Local\temp
2010-12-22 18:30 . 2008-05-07 18:59    99840    ----a-w-    c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
2010-12-22 06:08 . 2010-12-22 06:54    --------    d-----w-    c:\programdata\Recovery
2010-12-21 21:25 . 2010-12-22 07:00    --------    d-----w-    c:\windows\Internet Logs
2010-12-21 20:20 . 2010-12-21 20:20    --------    d-----w-    c:\program files (x86)\Sunbelt Software
2010-12-21 19:45 . 2010-12-21 19:45    --------    d-----w-    c:\program files (x86)\ESET
2010-12-20 22:08 . 2010-12-20 22:08    --------    d-----w-    c:\programdata\Malwarebytes
2010-12-20 22:08 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2010-12-20 19:45 . 2010-12-20 19:45    --------    d-----w-    c:\program files (x86)\Trend Micro
2010-12-20 19:18 . 2010-12-20 19:18    --------    d-----w-    c:\windows\system32\ZoneLabs
2010-12-20 19:05 . 2010-12-20 19:05    --------    d-----w-    c:\windows\system32\appmgmt
2010-12-17 20:56 . 2010-12-17 20:56    --------    d-----w-    c:\programdata\CheckPoint
2010-12-14 21:40 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\ConduitEngine
2010-12-14 21:40 . 2010-12-14 21:40    --------    d-----w-    C:\extensions
2010-12-13 20:39 . 2010-12-13 20:39    --------    d-----w-    c:\program files (x86)\Common Files\Java
2010-12-13 20:39 . 2010-12-13 20:39    --------    d-----w-    c:\program files (x86)\Java
2010-12-12 12:01 . 2010-12-12 12:01    --------    d-----w-    c:\program files (x86)\Hewlett-Packard
2010-12-10 16:11 . 2010-12-10 16:11    --------    d-----w-    c:\program files (x86)\Common Files\Windows Live
2010-12-09 22:56 . 2010-12-09 22:56    --------    d-----w-    c:\users\Default\AppData\Local\Microsoft Help
2010-12-09 22:44 . 2010-12-09 22:44    --------    d-----w-    c:\windows\Sun
2010-12-09 22:44 . 2010-12-09 22:44    521448    ----a-w-    c:\windows\system32\deployJava1.dll
2010-12-09 22:44 . 2010-12-09 22:44    --------    d-----w-    c:\program files\Java
2010-12-09 22:42 . 2010-12-09 22:42    --------    d-----w-    c:\program files (x86)\Common Files\Adobe
2010-12-09 21:20 . 2010-12-09 21:20    --------    d-sh--w-    c:\programdata\DSS
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\windows\SysWow64\AGEIA
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\program files (x86)\AGEIA Technologies
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\program files (x86)\Common Files\Wise Installation Wizard
2010-12-09 20:20 . 2010-12-09 20:28    --------    d-----w-    C:\Spil
2010-12-09 20:18 . 2010-12-09 20:19    --------    d-----w-    c:\program files (x86)\DAEMON Tools Lite
2010-12-09 19:34 . 2004-08-04 14:52    6067    ----a-w-    c:\windows\SysWow64\drivers\SnxUF2.sys
2010-12-09 19:34 . 2010-12-09 19:34    --------    d--h--w-    c:\program files (x86)\InstallShield Installation Information
2010-12-09 19:34 . 2010-12-09 19:34    --------    d-----w-    c:\program files (x86)\SHARKOON Technologies GmbH
2010-12-09 19:34 . 2004-08-19 16:30    46280    ----a-w-    c:\windows\SysWow64\drivers\UALFDrv2.sys
2010-12-09 19:34 . 2010-12-09 19:34    --------    d-----w-    c:\program files (x86)\Common Files\InstallShield
2010-12-09 19:00 . 2010-12-09 19:00    --------    d-----w-    c:\windows\SysWow64\Wat
2010-12-09 19:00 . 2010-12-09 19:00    --------    d-----w-    c:\windows\system32\Wat
2010-12-09 18:46 . 2010-12-09 18:46    --------    d-----w-    c:\program files\ESET
2010-12-09 18:27 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\CCleaner
2010-12-09 18:08 . 2010-12-09 18:12    --------    d-----w-    c:\program files (x86)\Microsoft Works
2010-12-09 18:08 . 2010-12-09 18:08    --------    d-----w-    c:\windows\PCHEALTH
2010-12-09 18:07 . 2010-12-09 18:07    --------    d-----w-    C:\IDE
2010-12-09 18:07 . 2010-12-09 18:07    --------    d-----w-    c:\program files (x86)\Microsoft Visual Studio 8
2010-12-09 18:06 . 2010-12-21 22:19    --------    d-----w-    c:\programdata\Microsoft Help
2010-12-09 18:06 . 2010-12-09 18:06    --------    d-----r-    C:\MSOCache
2010-12-09 18:00 . 2010-12-09 18:00    --------    d-----w-    c:\programdata\NVIDIA
2010-12-09 17:51 . 2010-12-09 17:51    --------    d-----w-    c:\programdata\NVIDIA Corporation
2010-12-09 17:51 . 2010-12-09 17:51    --------    d-----w-    c:\program files\NVIDIA Corporation
2010-12-09 17:50 . 2010-12-09 17:50    --------    d-----w-    c:\windows\SysWow64\RTCOM
2010-12-09 17:50 . 2010-12-09 17:50    --------    d-----w-    c:\program files\Realtek
2010-12-09 17:48 . 2010-12-09 18:08    --------    d-----w-    c:\program files (x86)\Microsoft.NET
2010-12-09 17:45 . 2009-07-13 18:01    3584    ----a-w-    c:\windows\system32\Spool\prtprocs\x64\da-DK\LXKPTPRC.DLL.mui
2010-12-09 17:45 . 2009-10-10 03:17    14336    ----a-w-    c:\windows\system32\drivers\sffp_sd.sys
2010-12-09 17:44 . 2010-03-04 04:32    243712    ----a-w-    c:\windows\system32\drivers\ks.sys
2010-12-09 17:43 . 2010-08-04 07:07    961024    ----a-w-    c:\windows\system32\CPFilters.dll
2010-12-09 17:43 . 2010-08-04 07:07    552960    ----a-w-    c:\windows\system32\msdri.dll
2010-12-09 17:43 . 2010-08-04 07:05    288256    ----a-w-    c:\windows\system32\MSNP.ax
2010-12-09 17:43 . 2010-08-04 07:05    258560    ----a-w-    c:\windows\system32\mpg2splt.ax
2010-12-09 17:43 . 2010-08-04 06:18    641536    ----a-w-    c:\windows\SysWow64\CPFilters.dll
2010-12-09 17:43 . 2010-08-04 06:15    204288    ----a-w-    c:\windows\SysWow64\MSNP.ax
2010-12-09 17:43 . 2010-08-04 06:15    199680    ----a-w-    c:\windows\SysWow64\mpg2splt.ax
2010-12-09 17:43 . 2009-12-13 09:46    613888    ----a-w-    c:\windows\system32\psisdecd.dll
2010-12-09 17:43 . 2009-12-13 09:30    465408    ----a-w-    c:\windows\SysWow64\psisdecd.dll
2010-12-09 17:43 . 2010-04-07 07:37    861184    ----a-w-    c:\windows\system32\oleaut32.dll
2010-12-09 17:43 . 2010-04-07 07:10    571904    ----a-w-    c:\windows\SysWow64\oleaut32.dll
2010-12-09 17:31 . 2009-11-25 11:47    99176    ----a-w-    c:\windows\SysWow64\PresentationHostProxy.dll
2010-12-09 17:31 . 2009-11-25 11:47    49472    ----a-w-    c:\windows\SysWow64\netfxperf.dll
2010-12-09 17:31 . 2009-11-25 11:47    48960    ----a-w-    c:\windows\system32\netfxperf.dll
2010-12-09 17:31 . 2009-11-25 11:47    297808    ----a-w-    c:\windows\SysWow64\mscoree.dll
2010-12-09 17:31 . 2009-11-25 11:47    295264    ----a-w-    c:\windows\SysWow64\PresentationHost.exe
2010-12-09 17:31 . 2009-11-25 11:47    1130824    ----a-w-    c:\windows\SysWow64\dfshim.dll
2010-12-09 17:31 . 2009-11-25 11:47    109912    ----a-w-    c:\windows\system32\PresentationHostProxy.dll
2010-12-09 17:31 . 2009-11-25 11:47    444752    ----a-w-    c:\windows\system32\mscoree.dll
2010-12-09 17:31 . 2009-11-25 11:47    320352    ----a-w-    c:\windows\system32\PresentationHost.exe
2010-12-09 17:31 . 2009-11-25 11:47    1942856    ----a-w-    c:\windows\system32\dfshim.dll
2010-12-09 17:30 . 2010-02-23 08:16    294912    ----a-w-    c:\windows\system32\browserchoice.exe
2010-12-09 17:26 . 2010-06-08 06:02    1233920    ----a-w-    c:\windows\SysWow64\msxml3.dll
2010-12-09 17:26 . 2010-06-08 05:36    1877504    ----a-w-    c:\windows\system32\msxml3.dll
2010-12-09 17:26 . 2010-05-19 19:48    144384    ----a-w-    c:\windows\system32\cdd.dll
2010-12-09 17:26 . 2010-08-26 05:27    148992    ----a-w-    c:\windows\system32\t2embed.dll
2010-12-09 17:26 . 2010-08-26 04:39    109056    ----a-w-    c:\windows\SysWow64\t2embed.dll
2010-12-09 17:26 . 2010-05-05 07:37    483840    ----a-w-    c:\windows\system32\StructuredQuery.dll
2010-12-09 17:26 . 2010-05-05 06:46    363520    ----a-w-    c:\windows\SysWow64\StructuredQuery.dll
2010-12-09 17:26 . 2010-08-21 06:38    1024512    ----a-w-    c:\windows\system32\wmpmde.dll
2010-12-09 17:26 . 2010-08-21 05:36    738816    ----a-w-    c:\windows\SysWow64\wmpmde.dll
2010-12-09 17:26 . 2009-10-19 14:46    100864    ----a-w-    c:\windows\system32\fontsub.dll
2010-12-09 17:26 . 2009-10-19 14:10    70656    ----a-w-    c:\windows\SysWow64\fontsub.dll
2010-12-09 17:21 . 2010-12-22 07:00    --------    d-----w-    c:\windows\SysWow64\Macromed
2010-12-09 17:19 . 2010-12-09 17:19    --------    d-sh--w-    c:\windows\SysWow64\%APPDATA%
2010-12-09 17:19 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\DAEMON Tools Toolbar
2010-12-09 17:18 . 2010-12-09 17:18    834544    ----a-w-    c:\windows\system32\drivers\sptd.sys
2010-12-09 17:18 . 2010-12-09 17:18    --------    d-----w-    c:\programdata\DAEMON Tools Lite
2010-12-09 17:18 . 2010-12-09 17:18    --------    d-----w-    c:\program files (x86)\Windows Live
2010-12-09 17:17 . 2010-12-09 17:17    --------    d-----w-    c:\program files\7-Zip
2010-12-09 17:17 . 2010-12-21 22:19    --------    d-sh--w-    c:\windows\Installer
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\program files (x86)\VideoLAN
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\custom matrices
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\C2MP
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\QuickTime
2010-12-09 17:15 . 2010-12-09 17:15    --------    d-----w-    c:\program files (x86)\Combined Community Codec Pack
2010-12-09 17:15 . 2010-12-09 17:15    --------    d-----w-    c:\program files (x86)\IObit

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-09 19:00 . 2009-12-18 17:16    419840    ----a-w-    c:\windows\system32\systemcpl.dll
2010-12-09 19:00 . 2009-07-13 23:52    14848    ----a-w-    c:\windows\system32\slwga.dll
2010-12-09 19:00 . 2009-07-13 23:36    13824    ----a-w-    c:\windows\SysWow64\slwga.dll
2010-12-09 19:00 . 2009-07-13 23:38    1008640    ----a-w-    c:\windows\system32\user32.dll
2010-12-09 19:00 . 2009-07-13 23:24    833024    ----a-w-    c:\windows\SysWow64\user32.dll
.

------- Sigcheck -------

  • 2010-12-09 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] . . c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] . . c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] . . c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
  • 2010-12-09 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] . . c:\windows\system32\user32.dll

  • 2010-12-09 . 861C4346F9281DC0380DE72C8D55D6BE . 833024 . . [6.1.7600.16385] . . c:\windows\SysWOW64\user32.dll
[7] 2009-07-14 . 72D7B3EA16946E8F0CF7458150031CC6 . 1008640 . . [6.1.7600.16385] . . c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] . . c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
  • 2010-12-09 . 2C353B6CE0C8D03225CAA2AF33B68D79 . 1008640 . . [6.1.7600.16385] . . c:\windows\system32\user32.dll
.
(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SHARKOON STATION"="c:\program files (x86)\SHARKOON Technologies GmbH\SHARKOON STATION\Majestic.exe" [2004-11-11 327680]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Welcome Center"="c:\windows\system32\rundll32.exe" [2009-07-14 44544]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 UALFDrv2;UALFDrv2;c:\windows\system32\DRIVERS\UALFDrv2.sys [x]
R3 WatAdminSvc;WatAdminSvc; [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-09 834544]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2009-11-16 123200]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]

.

--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-12-09 2715704]
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.mydtzone.com/startpage
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&ksporter til Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
.
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{57B012C9-5EAD-441B-9925-6B560B543D87}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.0.474.0"
"UniqueId"="001E420F4D012425"
"ScannerBuild"=dword:000017cd
"ScannerVersionId"=dword:00001214
"ScannerVersion"="Open window for status."
"FixId"=dword:00000007

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Gennemført tid: 2010-12-22  19:52:29
ComboFix-quarantined-files.txt  2010-12-22 18:52
ComboFix2.txt  2010-12-22 18:45
ComboFix3.txt  2010-12-20 20:30
ComboFix4.txt  2010-12-20 20:15

Pre-Kørsel: 926.516.776.960 byte ledig
Post-Kørsel: 926.464.667.648 byte ledig

- - End Of File - - 3C4C4C3EA27462C0C2242D31ACCF8712
Avatar billede f-arn Guru
22. december 2010 - 21:35 #21
1. Hent Defogger og gem programmet på dit Skrivebord:

http://www.jpshortstuff.247fixes.com/Defogger.exe

2. Dobbeltklik på Defogger.exe - et vindue vil åbne sig - klik på "Disable" og klik "Yes" for at fortsætte. Nu vil programmet deaktivere dit CD-emulations program og afslutte med "Finished!" - klik "OK". NB - efter rensning vil vi aktivere dit CD-emulations program igen; ingen grund til bekymring.

3. Defogger vil nu genstarte din computer - klik OK.

------

Højreklik på skrivebordet og vælg ny->tekstdokument og kopier det fremhævede ind og gem filen som CFScript

Killall::
Snapshot::
FCopy::
c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll | c:\windows\system32\user32.dll
c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll | c:\windows\SysWow64\user32.dll
Filelook::
c:\windows\system32\slwga.dll
c:\program files (x86)\SHARKOON Technologies GmbH\SHARKOON STATION\Majestic.exe


Da Combofix kan konflikte med dine sikkerhedsprogrammer er det vigtigt at du deaktiverer dem.

Tag så fat i den nye fil med musen, og før den hen over Combofix-filen, hvorefter du "giver slip" med musen.
http://www.fromsej.saknet.dk/billeder/cfscript.gif

Så skulle Combofix gerne give sig til at arbejde. Muligvis vil den kræve en genstart, hvilket du skal tillade. Du bør ikke klikke på vinduet imens værktøjet kører, idet det kan få din computer til at fryse.
Når Combofix er færdig, og efter det (muligvis) har genstartet, skulle der gerne åbnes en logfil combofix.txt som ligger her C:\Combofix.txt

Indholdet af denne fil må du gerne lægge herind.
Avatar billede missus Nybegynder
22. december 2010 - 22:05 #22
kommer her:

ComboFix 10-12-22.01 - Missus 22-12-2010  21:58:39.3.4 - x64
Microsoft Windows 7 Ultimate  6.1.7600.0.1252.45.1033.18.6007.4883 [GMT 1:00]
Kører fra: c:\users\Missus\Desktop\ComboFix.exe
Kommandoer benyttet :: c:\users\Missus\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {CB0F8167-5331-BA19-698E-64816B6801A5}
SP: ESET NOD32 Antivirus 4.0 *Disabled/Updated* {706E6083-750B-B597-533E-5FF310EF4B18}
.

(((((((((((((((((((((((((((((((((((((((  Andet, der er slettet  )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\winsxs\amd64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_292d5de8870d85d9\user32.dll --> c:\windows\system32\user32.dll
c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll --> c:\windows\SysWow64\user32.dll
.
(((((((((((((((((((((((((((((  Filer skabt fra 2010-11-22 til 2010-12-22  )))))))))))))))))))))))))))))))))))
.

2010-12-22 21:00 . 2010-12-22 21:00    --------    d-----w-    c:\users\Default\AppData\Local\temp
2010-12-22 20:35 . 2010-12-22 20:35    411368    ----a-w-    c:\windows\SysWow64\deploytk.dll
2010-12-22 20:33 . 2010-12-22 20:33    --------    d-----w-    c:\program files\Java
2010-12-22 18:30 . 2008-05-07 18:59    99840    ----a-w-    c:\windows\system32\Spool\prtprocs\x64\HPZPPLHN.DLL
2010-12-22 06:08 . 2010-12-22 06:54    --------    d-----w-    c:\programdata\Recovery
2010-12-21 21:25 . 2010-12-22 07:00    --------    d-----w-    c:\windows\Internet Logs
2010-12-21 20:20 . 2010-12-21 20:20    --------    d-----w-    c:\program files (x86)\Sunbelt Software
2010-12-21 19:45 . 2010-12-21 19:45    --------    d-----w-    c:\program files (x86)\ESET
2010-12-20 22:08 . 2010-12-20 22:08    --------    d-----w-    c:\programdata\Malwarebytes
2010-12-20 22:08 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\Malwarebytes' Anti-Malware
2010-12-20 19:45 . 2010-12-20 19:45    --------    d-----w-    c:\program files (x86)\Trend Micro
2010-12-20 19:18 . 2010-12-20 19:18    --------    d-----w-    c:\windows\system32\ZoneLabs
2010-12-20 19:05 . 2010-12-20 19:05    --------    d-----w-    c:\windows\system32\appmgmt
2010-12-17 20:56 . 2010-12-17 20:56    --------    d-----w-    c:\programdata\CheckPoint
2010-12-14 21:40 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\ConduitEngine
2010-12-14 21:40 . 2010-12-14 21:40    --------    d-----w-    C:\extensions
2010-12-13 20:39 . 2010-12-13 20:39    --------    d-----w-    c:\program files (x86)\Common Files\Java
2010-12-13 20:39 . 2010-12-13 20:39    --------    d-----w-    c:\program files (x86)\Java
2010-12-12 12:01 . 2010-12-12 12:01    --------    d-----w-    c:\program files (x86)\Hewlett-Packard
2010-12-10 16:11 . 2010-12-10 16:11    --------    d-----w-    c:\program files (x86)\Common Files\Windows Live
2010-12-09 22:56 . 2010-12-09 22:56    --------    d-----w-    c:\users\Default\AppData\Local\Microsoft Help
2010-12-09 22:44 . 2010-12-09 22:44    --------    d-----w-    c:\windows\Sun
2010-12-09 22:44 . 2010-12-22 20:33    521448    ----a-w-    c:\windows\system32\deployJava1.dll
2010-12-09 22:42 . 2010-12-09 22:42    --------    d-----w-    c:\program files (x86)\Common Files\Adobe
2010-12-09 21:20 . 2010-12-09 21:20    --------    d-sh--w-    c:\programdata\DSS
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\windows\SysWow64\AGEIA
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\program files (x86)\AGEIA Technologies
2010-12-09 20:21 . 2010-12-09 20:21    --------    d-----w-    c:\program files (x86)\Common Files\Wise Installation Wizard
2010-12-09 20:20 . 2010-12-09 20:28    --------    d-----w-    C:\Spil
2010-12-09 20:18 . 2010-12-09 20:19    --------    d-----w-    c:\program files (x86)\DAEMON Tools Lite
2010-12-09 19:34 . 2004-08-04 14:52    6067    ----a-w-    c:\windows\SysWow64\drivers\SnxUF2.sys
2010-12-09 19:34 . 2010-12-09 19:34    --------    d--h--w-    c:\program files (x86)\InstallShield Installation Information
2010-12-09 19:34 . 2010-12-09 19:34    --------    d-----w-    c:\program files (x86)\SHARKOON Technologies GmbH
2010-12-09 19:34 . 2004-08-19 16:30    46280    ----a-w-    c:\windows\SysWow64\drivers\UALFDrv2.sys
2010-12-09 19:34 . 2010-12-09 19:34    --------    d-----w-    c:\program files (x86)\Common Files\InstallShield
2010-12-09 19:00 . 2010-12-09 19:00    --------    d-----w-    c:\windows\SysWow64\Wat
2010-12-09 19:00 . 2010-12-09 19:00    --------    d-----w-    c:\windows\system32\Wat
2010-12-09 18:46 . 2010-12-09 18:46    --------    d-----w-    c:\program files\ESET
2010-12-09 18:27 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\CCleaner
2010-12-09 18:08 . 2010-12-09 18:12    --------    d-----w-    c:\program files (x86)\Microsoft Works
2010-12-09 18:08 . 2010-12-09 18:08    --------    d-----w-    c:\windows\PCHEALTH
2010-12-09 18:07 . 2010-12-09 18:07    --------    d-----w-    C:\IDE
2010-12-09 18:07 . 2010-12-09 18:07    --------    d-----w-    c:\program files (x86)\Microsoft Visual Studio 8
2010-12-09 18:06 . 2010-12-21 22:19    --------    d-----w-    c:\programdata\Microsoft Help
2010-12-09 18:06 . 2010-12-09 18:06    --------    d-----r-    C:\MSOCache
2010-12-09 18:00 . 2010-12-09 18:00    --------    d-----w-    c:\programdata\NVIDIA
2010-12-09 17:51 . 2010-12-09 17:51    --------    d-----w-    c:\programdata\NVIDIA Corporation
2010-12-09 17:51 . 2010-12-09 17:51    --------    d-----w-    c:\program files\NVIDIA Corporation
2010-12-09 17:50 . 2010-12-09 17:50    --------    d-----w-    c:\windows\SysWow64\RTCOM
2010-12-09 17:50 . 2010-12-09 17:50    --------    d-----w-    c:\program files\Realtek
2010-12-09 17:48 . 2010-12-09 18:08    --------    d-----w-    c:\program files (x86)\Microsoft.NET
2010-12-09 17:45 . 2009-07-13 18:01    3584    ----a-w-    c:\windows\system32\Spool\prtprocs\x64\da-DK\LXKPTPRC.DLL.mui
2010-12-09 17:45 . 2009-10-10 03:17    14336    ----a-w-    c:\windows\system32\drivers\sffp_sd.sys
2010-12-09 17:44 . 2010-03-04 04:32    243712    ----a-w-    c:\windows\system32\drivers\ks.sys
2010-12-09 17:43 . 2010-08-04 07:07    961024    ----a-w-    c:\windows\system32\CPFilters.dll
2010-12-09 17:43 . 2010-08-04 07:07    552960    ----a-w-    c:\windows\system32\msdri.dll
2010-12-09 17:43 . 2010-08-04 07:05    288256    ----a-w-    c:\windows\system32\MSNP.ax
2010-12-09 17:43 . 2010-08-04 07:05    258560    ----a-w-    c:\windows\system32\mpg2splt.ax
2010-12-09 17:43 . 2010-08-04 06:18    641536    ----a-w-    c:\windows\SysWow64\CPFilters.dll
2010-12-09 17:43 . 2010-08-04 06:15    204288    ----a-w-    c:\windows\SysWow64\MSNP.ax
2010-12-09 17:43 . 2010-08-04 06:15    199680    ----a-w-    c:\windows\SysWow64\mpg2splt.ax
2010-12-09 17:43 . 2009-12-13 09:46    613888    ----a-w-    c:\windows\system32\psisdecd.dll
2010-12-09 17:43 . 2009-12-13 09:30    465408    ----a-w-    c:\windows\SysWow64\psisdecd.dll
2010-12-09 17:43 . 2010-04-07 07:37    861184    ----a-w-    c:\windows\system32\oleaut32.dll
2010-12-09 17:43 . 2010-04-07 07:10    571904    ----a-w-    c:\windows\SysWow64\oleaut32.dll
2010-12-09 17:31 . 2009-11-25 11:47    99176    ----a-w-    c:\windows\SysWow64\PresentationHostProxy.dll
2010-12-09 17:31 . 2009-11-25 11:47    49472    ----a-w-    c:\windows\SysWow64\netfxperf.dll
2010-12-09 17:31 . 2009-11-25 11:47    48960    ----a-w-    c:\windows\system32\netfxperf.dll
2010-12-09 17:31 . 2009-11-25 11:47    297808    ----a-w-    c:\windows\SysWow64\mscoree.dll
2010-12-09 17:31 . 2009-11-25 11:47    295264    ----a-w-    c:\windows\SysWow64\PresentationHost.exe
2010-12-09 17:31 . 2009-11-25 11:47    1130824    ----a-w-    c:\windows\SysWow64\dfshim.dll
2010-12-09 17:31 . 2009-11-25 11:47    109912    ----a-w-    c:\windows\system32\PresentationHostProxy.dll
2010-12-09 17:31 . 2009-11-25 11:47    444752    ----a-w-    c:\windows\system32\mscoree.dll
2010-12-09 17:31 . 2009-11-25 11:47    320352    ----a-w-    c:\windows\system32\PresentationHost.exe
2010-12-09 17:31 . 2009-11-25 11:47    1942856    ----a-w-    c:\windows\system32\dfshim.dll
2010-12-09 17:30 . 2010-02-23 08:16    294912    ----a-w-    c:\windows\system32\browserchoice.exe
2010-12-09 17:26 . 2010-06-08 06:02    1233920    ----a-w-    c:\windows\SysWow64\msxml3.dll
2010-12-09 17:26 . 2010-06-08 05:36    1877504    ----a-w-    c:\windows\system32\msxml3.dll
2010-12-09 17:26 . 2010-05-19 19:48    144384    ----a-w-    c:\windows\system32\cdd.dll
2010-12-09 17:26 . 2010-08-26 05:27    148992    ----a-w-    c:\windows\system32\t2embed.dll
2010-12-09 17:26 . 2010-08-26 04:39    109056    ----a-w-    c:\windows\SysWow64\t2embed.dll
2010-12-09 17:26 . 2010-05-05 07:37    483840    ----a-w-    c:\windows\system32\StructuredQuery.dll
2010-12-09 17:26 . 2010-05-05 06:46    363520    ----a-w-    c:\windows\SysWow64\StructuredQuery.dll
2010-12-09 17:26 . 2010-08-21 06:38    1024512    ----a-w-    c:\windows\system32\wmpmde.dll
2010-12-09 17:26 . 2010-08-21 05:36    738816    ----a-w-    c:\windows\SysWow64\wmpmde.dll
2010-12-09 17:26 . 2009-10-19 14:46    100864    ----a-w-    c:\windows\system32\fontsub.dll
2010-12-09 17:26 . 2009-10-19 14:10    70656    ----a-w-    c:\windows\SysWow64\fontsub.dll
2010-12-09 17:21 . 2010-12-22 07:00    --------    d-----w-    c:\windows\SysWow64\Macromed
2010-12-09 17:19 . 2010-12-09 17:19    --------    d-sh--w-    c:\windows\SysWow64\%APPDATA%
2010-12-09 17:19 . 2010-12-22 07:00    --------    d-----w-    c:\program files (x86)\DAEMON Tools Toolbar
2010-12-09 17:18 . 2010-12-09 17:18    834544    ----a-w-    c:\windows\system32\drivers\sptd.sys
2010-12-09 17:18 . 2010-12-09 17:18    --------    d-----w-    c:\programdata\DAEMON Tools Lite
2010-12-09 17:18 . 2010-12-09 17:18    --------    d-----w-    c:\program files (x86)\Windows Live
2010-12-09 17:17 . 2010-12-09 17:17    --------    d-----w-    c:\program files\7-Zip
2010-12-09 17:17 . 2010-12-22 20:36    --------    d-sh--w-    c:\windows\Installer
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\program files (x86)\VideoLAN
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\custom matrices
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\C2MP
2010-12-09 17:16 . 2010-12-09 17:16    --------    d-----w-    c:\windows\SysWow64\QuickTime
2010-12-09 17:15 . 2010-12-09 17:15    --------    d-----w-    c:\program files (x86)\Combined Community Codec Pack
2010-12-09 17:15 . 2010-12-09 17:15    --------    d-----w-    c:\program files (x86)\IObit

.
((((((((((((((((((((((((((((((((((((((((  Find3M Rapport  ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-09 19:00 . 2009-12-18 17:16    419840    ----a-w-    c:\windows\system32\systemcpl.dll
2010-12-09 19:00 . 2009-07-13 23:52    14848    ----a-w-    c:\windows\system32\slwga.dll
2010-12-09 19:00 . 2009-07-13 23:36    13824    ----a-w-    c:\windows\SysWow64\slwga.dll
.

((((((((((((((((((((((((((((((((((((((((((((  Look  )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

--- c:\program files (x86)\SHARKOON Technologies GmbH\SHARKOON STATION\Majestic.exe ---
Company:
File Description: SHARKOON STATION
File Version: 2, 0, 0, 0
Product Name: Sharkoon Majestic 5.1 USB
Copyright: Copyright (C) 2003-2004
Original Filename: MAJESTIC.EXE
File size: 327680
Created time: 2010-12-09 19:34
Modified time: 2004-11-11 17:31
MD5: 4F076542C4884E4E8D03C3CDFB38E995
SHA1: 007E8B340F750F3633AD6A2AA162BA0567732EDB


--- c:\windows\system32\slwga.dll ---
Company: Microsoft Corporation
File Description: Software Licensing WGA API
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Name: Microsoft® Windows® Operating System
Copyright: © Microsoft Corporation. All rights reserved.
Original Filename: slwga.dll
File size: 13824
Created time: 2009-07-13 23:36
Modified time: 2010-12-09 19:00
MD5: E61F59694F03806C39E39260B7F17ACD
SHA1: C868D9765AD771CBB86BFC99663AC1DBA3A819D8


(((((((((((((((((((((((((((((((((((  Start steder i reg.basen  ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Bemærk* tomme linier & lovlige standard linier vises ikke 
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SHARKOON STATION"="c:\program files (x86)\SHARKOON Technologies GmbH\SHARKOON STATION\Majestic.exe" [2004-11-11 327680]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2009-12-17 149224]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Welcome Center"="c:\windows\system32\rundll32.exe" [2009-07-14 44544]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 UALFDrv2;UALFDrv2;c:\windows\system32\DRIVERS\UALFDrv2.sys [x]
R3 WatAdminSvc;WatAdminSvc; [x]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-12-09 834544]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-11-16 136584]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [2009-11-16 735960]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2009-11-16 123200]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]

.

--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2010-12-09 2715704]
.
------- Yderligere scanning -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.eb.dk/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&ksporter til Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
.
.
--------------------- LÅSTE REGISTRERINGS NØGLER ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx"
"ThreadingModel"="Apartment"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10l.ocx, 1"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (2) (LocalSystem)
"AppDataDir"="c:\\ProgramData\\ESET\\ESET NOD32 Antivirus\\"
"DataDir"="ESET\\ESET NOD32 Antivirus\\"
"EditionName"=" "
"InstallDir"="c:\\Program Files\\ESET\\ESET NOD32 Antivirus\\"
"LanguageId"=dword:00000409
"PackageTag"=dword:6090e758
"ProductBase"=dword:00000000
"ProductCode"="{57B012C9-5EAD-441B-9925-6B560B543D87}"
"ProductName"="ESET NOD32 Antivirus"
"ProductType"="eav"
"ProductVersion"="4.0.474.0"
"UniqueId"="001E420F4D012425"
"ScannerBuild"=dword:000017cd
"ScannerVersionId"=dword:00001214
"ScannerVersion"="Open window for status."
"FixId"=dword:00000007

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Andre kørende processer ------------------------
.
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
.
**************************************************************************
.
Gennemført tid: 2010-12-22  22:03:57 - maskinen blev genstartet
ComboFix-quarantined-files.txt  2010-12-22 21:03
ComboFix2.txt  2010-12-22 18:52
ComboFix3.txt  2010-12-22 18:45
ComboFix4.txt  2010-12-20 20:30
ComboFix5.txt  2010-12-22 20:58

Pre-Kørsel: 929.128.140.800 byte ledig
Post-Kørsel: 928.713.826.304 byte ledig

- - End Of File - - 7398A90FB9FA48C3DD3BCE49EF25AB7D
Avatar billede f-arn Guru
23. december 2010 - 04:53 #23
Hent http://go.microsoft.com/fwlink/?linkid=52012
Start den, og klik "continue"
Klik copy og indsæt det i Notesblok.
Sæt X i stedet for din produkt nøgle.
Kopier loggen herind.
Avatar billede missus Nybegynder
23. december 2010 - 16:56 #24
Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->

Validation Code: 0
Cached Online Validation Code: N/A, hr = 0xc004f012
Windows Product Key: xxxxx-xxxxx-xxxxx-xxxxx-xxxxx
Windows Product Key Hash: 55n8g6xdzhe4AOWhmTzdzQoLfa4=
Windows Product ID: 00426-292-0000007-85275
Windows Product ID Type: 5
Windows License Type: Retail
Windows OS version: 6.1.7600.2.00010100.0.0.001
ID: {9CAE687C-16AB-4C36-8760-D0027B49F1C6}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Seven Black Edition
Architecture: 0x00000009
Build lab: 7600.win7_gdr.100618-1621
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 103 Blocked VLK
Microsoft Office Enterprise 2007 - 103 Blocked VLK
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->
File Mismatch: C:\Windows\system32\wat\watadminsvc.exe[Hr = 0x80070005]
File Mismatch: C:\Windows\system32\wat\watux.exe[Hr = 0x80070005]
File Mismatch: C:\Windows\system32\slui.exe[6.1.7600.16385], Hr = 0x80092003
File Mismatch: C:\Windows\system32\systemcpl.dll[6.1.7600.16385], Hr = 0x800b0100

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{9CAE687C-16AB-4C36-8760-D0027B49F1C6}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7600.2.00010100.0.0.001</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-3MBMV</PKey><PID>00426-292-0000007-85275</PID><PIDType>5</PIDType><SID>S-1-5-21-2597269197-1032137373-2519002587</SID><SYSTEM><Manufacturer>Hewlett-Packard</Manufacturer><Model>p6669sc</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>6.13</Version><SMBIOSVersion major="2" minor="6"/><Date>20101006000000.000000+000</Date></BIOS><HWID>58BB3607018400FC</HWID><UserLCID>0406</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Rom, normaltid(GMT+01:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>HPQOEM</OEMID><OEMTableID>SLIC-CPC</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>103</Result><Products><Product GUID="{90120000-0030-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>ACD7202654E586</Val><Hash>fFic3JgCreGGRxyF8uMWB4R4Jcg=</Hash><Pid>89388-707-1528066-65453</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="103"/><App Id="16" Version="12" Result="103"/><App Id="18" Version="12" Result="103"/><App Id="19" Version="12" Result="103"/><App Id="1A" Version="12" Result="103"/><App Id="1B" Version="12" Result="103"/><App Id="44" Version="12" Result="103"/><App Id="A1" Version="12" Result="103"/><App Id="BA" Version="12" Result="103"/></Applications></Office></Software></GenuineResults> 

Spsys.log Content: 0x80070002

Licensing Data-->
Inputfejl: Scriptfilen "C:\Windows\system32\slmgr.vbs" blev ikke fundet.

Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: N/A
HealthStatus: 0x0000000000000000
Event Time Stamp: N/A
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Not Registered - 0x80070005
HealthStatus Bitmask Output:


HWID Data-->
HWID Hash Current: LgAAAAEAAAABAAEAAQADAAAAAQABAAEAonai64x4mLGUn8QxilICTEmVKNdcXQ==

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
  ACPI Table Name    OEMID Value    OEMTableID Value
  APIC            HPQOEM        SLIC-CPC
  FACP            HPQOEM        SLIC-CPC
  HPET            HPQOEM        SLIC-CPC
  MCFG            HPQOEM        SLIC-CPC
  SLIC            HPQOEM        SLIC-CPC
  OEMB            HPQOEM        SLIC-CPC
  SSDT            HPQOEM        SLIC-CPC
  GSCI            HPQOEM        SLIC-CPC
  SSDT            HPQOEM        SLIC-CPC
Avatar billede missus Nybegynder
23. december 2010 - 20:38 #25
?
Avatar billede f-arn Guru
23. december 2010 - 22:06 #26
Der er noget helt galt med din Windows. Der er manglende/korrupte filer, der forhindrer at den kan valideres. Det er vel også derfor. du brugte denne:

c:\Users\Missus\Desktop\removewat.exe (HackTool.Wpakill)

Hvis det er en legal Windows, vil jeg anbefale at du prøver dette:
http://windows7forums.com/da/tweaks-guides-howto/19250-system-file-checker-en-fantastisk-windows-fix-v%C3%A6rkt%C3%B8j.html

Du skal sikkert bruge din Produkt - nøgle.
Avatar billede missus Nybegynder
23. december 2010 - 23:04 #27
ok - jeg tror det blev løst allerede med Tdsskiller.zip for da stoppede pc med at komme med alerts så smid et svar :-)
Avatar billede f-arn Guru
24. december 2010 - 07:22 #28
Jeg er slet ikke i tvivl om, at den infektion kom, fra brug af bl.a ovennævte. Du bør for din egen skyld ikke bruge Cracks og Keygens. Der er næsten altid "præmier" med !
Avatar billede missus Nybegynder
24. december 2010 - 10:39 #29
mange tak for hjælpen
Avatar billede f-arn Guru
24. december 2010 - 10:46 #30
Kør defogger og aktiver dit CD-emulations program igen.

------

Tast  <Windows> + <R> samtidig og kopier dettte: combofix /uninstall
Tryk enter
Det vil fjerne Combofix og nulstille urets indstillinger.
Nulstille systemgendannelsen.
Skjule filtypenavne hvis det kræves.
Skjule System/skjulte filer hvis det kræves.
Avatar billede missus Nybegynder
24. december 2010 - 14:16 #31
ok endnu engang tak for hjælpen
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester